Compare commits

...
Author SHA1 Message Date
Hugo P.Brito 3752b5328a fix(api): document Azure certificate credentials 2026-08-24 12:25:06 +01:00
mintlify[bot] 5202a68cf0 docs: brand tone and writing style fixes (#12510)
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-08-24 11:17:37 +02:00
14 changed files with 340 additions and 52 deletions
@@ -0,0 +1 @@
`POST /api/v1/providers` OpenAPI schema documents Azure certificate authentication credentials
+265 -41
View File
@@ -6091,16 +6091,6 @@ paths:
schema:
type: string
format: date
- in: query
name: filter[updated_at__gte]
schema:
type: string
format: date-time
- in: query
name: filter[updated_at__lte]
schema:
type: string
format: date-time
- name: sort
required: false
in: query
@@ -16312,7 +16302,7 @@ paths:
content:
application/vnd.api+json:
schema:
$ref: '#/components/schemas/UserResponse'
$ref: '#/components/schemas/UserMeResponse'
description: ''
components:
schemas:
@@ -16444,6 +16434,17 @@ components:
type: array
items:
$ref: '#/components/schemas/AttackPathsQueryParameter'
outcome:
type: object
nullable: true
properties:
kind:
type: string
label:
type: string
partial:
type: boolean
readOnly: true
required:
- id
- name
@@ -17680,7 +17681,11 @@ components:
can be generated from your Atlassian account settings.
domain:
type: string
description: The JIRA domain/instance URL (e.g., 'your-domain.atlassian.net').
description: The Jira site name without the '.atlassian.net' suffix
(e.g., 'your-domain').
minLength: 1
maxLength: 63
pattern: ^[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?$
required:
- user_mail
- api_token
@@ -17865,7 +17870,11 @@ components:
can be generated from your Atlassian account settings.
domain:
type: string
description: The JIRA domain/instance URL (e.g., 'your-domain.atlassian.net').
description: The Jira site name without the '.atlassian.net'
suffix (e.g., 'your-domain').
minLength: 1
maxLength: 63
pattern: ^[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?$
required:
- user_mail
- api_token
@@ -18127,7 +18136,11 @@ components:
can be generated from your Atlassian account settings.
domain:
type: string
description: The JIRA domain/instance URL (e.g., 'your-domain.atlassian.net').
description: The Jira site name without the '.atlassian.net' suffix
(e.g., 'your-domain').
minLength: 1
maxLength: 63
pattern: ^[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?$
required:
- user_mail
- api_token
@@ -20554,7 +20567,11 @@ components:
can be generated from your Atlassian account settings.
domain:
type: string
description: The JIRA domain/instance URL (e.g., 'your-domain.atlassian.net').
description: The Jira site name without the '.atlassian.net'
suffix (e.g., 'your-domain').
minLength: 1
maxLength: 63
pattern: ^[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?$
required:
- user_mail
- api_token
@@ -21272,7 +21289,7 @@ components:
- role_arn
- external_id
- type: object
title: Azure Static Credentials
title: Azure Client Secret Credentials
properties:
client_id:
type: string
@@ -21290,6 +21307,27 @@ components:
- client_id
- client_secret
- tenant_id
additionalProperties: false
- type: object
title: Azure Certificate Credentials
properties:
client_id:
type: string
description: The Azure application (client) ID for authentication
in Azure AD.
certificate_content:
type: string
description: Base64-encoded PEM certificate and private key
content for certificate-based authentication.
tenant_id:
type: string
description: The Azure tenant ID, representing the directory
where the application is registered.
required:
- client_id
- certificate_content
- tenant_id
additionalProperties: false
- type: object
title: M365 Static Credentials
properties:
@@ -21387,7 +21425,8 @@ components:
kubeconfig_content:
type: string
description: The content of the Kubernetes kubeconfig file,
encoded as a string.
encoded as a string. Kubeconfig command-based authentication
is not supported in Prowler Cloud for security reasons.
required:
- kubeconfig_content
- type: object
@@ -21450,18 +21489,23 @@ components:
tenancy:
type: string
description: The OCID of the tenancy.
region:
type: string
description: The OCI region identifier (e.g., us-ashburn-1,
us-phoenix-1).
pass_phrase:
type: string
description: The passphrase for the private key, if encrypted.
region:
type: string
deprecated: true
description: Legacy OCI region field accepted for backwards
compatibility but ignored; OCI scans all regions.
required:
- user
- fingerprint
- tenancy
- region
anyOf:
- required:
- key_file
- required:
- key_content
- type: object
title: MongoDB Atlas API Key
properties:
@@ -23396,7 +23440,7 @@ components:
- role_arn
- external_id
- type: object
title: Azure Static Credentials
title: Azure Client Secret Credentials
properties:
client_id:
type: string
@@ -23414,6 +23458,27 @@ components:
- client_id
- client_secret
- tenant_id
additionalProperties: false
- type: object
title: Azure Certificate Credentials
properties:
client_id:
type: string
description: The Azure application (client) ID for authentication
in Azure AD.
certificate_content:
type: string
description: Base64-encoded PEM certificate and private key content
for certificate-based authentication.
tenant_id:
type: string
description: The Azure tenant ID, representing the directory where
the application is registered.
required:
- client_id
- certificate_content
- tenant_id
additionalProperties: false
- type: object
title: M365 Static Credentials
properties:
@@ -23510,7 +23575,8 @@ components:
kubeconfig_content:
type: string
description: The content of the Kubernetes kubeconfig file, encoded
as a string.
as a string. Kubeconfig command-based authentication is not
supported in Prowler Cloud for security reasons.
required:
- kubeconfig_content
- type: object
@@ -23572,17 +23638,23 @@ components:
tenancy:
type: string
description: The OCID of the tenancy.
region:
type: string
description: The OCI region identifier (e.g., us-ashburn-1, us-phoenix-1).
pass_phrase:
type: string
description: The passphrase for the private key, if encrypted.
region:
type: string
deprecated: true
description: Legacy OCI region field accepted for backwards compatibility
but ignored; OCI scans all regions.
required:
- user
- fingerprint
- tenancy
- region
anyOf:
- required:
- key_file
- required:
- key_content
- type: object
title: MongoDB Atlas API Key
properties:
@@ -23835,7 +23907,7 @@ components:
- role_arn
- external_id
- type: object
title: Azure Static Credentials
title: Azure Client Secret Credentials
properties:
client_id:
type: string
@@ -23853,6 +23925,27 @@ components:
- client_id
- client_secret
- tenant_id
additionalProperties: false
- type: object
title: Azure Certificate Credentials
properties:
client_id:
type: string
description: The Azure application (client) ID for authentication
in Azure AD.
certificate_content:
type: string
description: Base64-encoded PEM certificate and private key
content for certificate-based authentication.
tenant_id:
type: string
description: The Azure tenant ID, representing the directory
where the application is registered.
required:
- client_id
- certificate_content
- tenant_id
additionalProperties: false
- type: object
title: M365 Static Credentials
properties:
@@ -23950,7 +24043,8 @@ components:
kubeconfig_content:
type: string
description: The content of the Kubernetes kubeconfig file,
encoded as a string.
encoded as a string. Kubeconfig command-based authentication
is not supported in Prowler Cloud for security reasons.
required:
- kubeconfig_content
- type: object
@@ -24013,18 +24107,23 @@ components:
tenancy:
type: string
description: The OCID of the tenancy.
region:
type: string
description: The OCI region identifier (e.g., us-ashburn-1,
us-phoenix-1).
pass_phrase:
type: string
description: The passphrase for the private key, if encrypted.
region:
type: string
deprecated: true
description: Legacy OCI region field accepted for backwards
compatibility but ignored; OCI scans all regions.
required:
- user
- fingerprint
- tenancy
- region
anyOf:
- required:
- key_file
- required:
- key_content
- type: object
title: MongoDB Atlas API Key
properties:
@@ -24297,7 +24396,7 @@ components:
- role_arn
- external_id
- type: object
title: Azure Static Credentials
title: Azure Client Secret Credentials
properties:
client_id:
type: string
@@ -24315,6 +24414,27 @@ components:
- client_id
- client_secret
- tenant_id
additionalProperties: false
- type: object
title: Azure Certificate Credentials
properties:
client_id:
type: string
description: The Azure application (client) ID for authentication
in Azure AD.
certificate_content:
type: string
description: Base64-encoded PEM certificate and private key content
for certificate-based authentication.
tenant_id:
type: string
description: The Azure tenant ID, representing the directory where
the application is registered.
required:
- client_id
- certificate_content
- tenant_id
additionalProperties: false
- type: object
title: M365 Static Credentials
properties:
@@ -24411,7 +24531,8 @@ components:
kubeconfig_content:
type: string
description: The content of the Kubernetes kubeconfig file, encoded
as a string.
as a string. Kubeconfig command-based authentication is not
supported in Prowler Cloud for security reasons.
required:
- kubeconfig_content
- type: object
@@ -24473,17 +24594,23 @@ components:
tenancy:
type: string
description: The OCID of the tenancy.
region:
type: string
description: The OCI region identifier (e.g., us-ashburn-1, us-phoenix-1).
pass_phrase:
type: string
description: The passphrase for the private key, if encrypted.
region:
type: string
deprecated: true
description: Legacy OCI region field accepted for backwards compatibility
but ignored; OCI scans all regions.
required:
- user
- fingerprint
- tenancy
- region
anyOf:
- required:
- key_file
- required:
- key_content
- type: object
title: MongoDB Atlas API Key
properties:
@@ -26809,6 +26936,103 @@ components:
$ref: '#/components/schemas/UserCreate'
required:
- data
UserMe:
type: object
required:
- type
- id
additionalProperties: false
properties:
type:
type: string
description: The [type](https://jsonapi.org/format/#document-resource-object-identification)
member is used to describe resource objects that share common attributes
and relationships.
enum:
- users
id:
type: string
format: uuid
attributes:
type: object
properties:
name:
type: string
maxLength: 150
minLength: 3
email:
type: string
format: email
description: Case insensitive
maxLength: 254
company_name:
type: string
maxLength: 150
date_joined:
type: string
format: date-time
readOnly: true
required:
- name
- email
relationships:
type: object
properties:
memberships:
type: object
properties:
data:
type: object
properties:
id:
type: string
type:
type: string
enum:
- memberships
title: Resource Type Name
description: The [type](https://jsonapi.org/format/#document-resource-object-identification)
member is used to describe resource objects that share common
attributes and relationships.
required:
- id
- type
required:
- data
description: The identifier of the related object.
title: Resource Identifier
readOnly: true
roles:
type: object
properties:
data:
type: object
properties:
id:
type: string
type:
type: string
enum:
- roles
title: Resource Type Name
description: The [type](https://jsonapi.org/format/#document-resource-object-identification)
member is used to describe resource objects that share common
attributes and relationships.
required:
- id
- type
required:
- data
description: The identifier of the related object.
title: Resource Identifier
readOnly: true
UserMeResponse:
type: object
properties:
data:
$ref: '#/components/schemas/UserMe'
required:
- data
UserResponse:
type: object
properties:
@@ -244,6 +244,47 @@ class TestOracleCloudProviderSecret:
class TestProviderSecretFieldSchema:
def test_azure_schema_exposes_exclusive_supported_credential_shapes(self):
schema = ProviderSecretField._spectacular_annotation["field"]
azure_schemas = {
credential_schema["title"]: credential_schema
for credential_schema in schema["oneOf"]
if credential_schema["title"].startswith("Azure ")
}
assert set(azure_schemas) == {
"Azure Client Secret Credentials",
"Azure Certificate Credentials",
}
assert azure_schemas["Azure Client Secret Credentials"]["required"] == [
"client_id",
"client_secret",
"tenant_id",
]
assert set(azure_schemas["Azure Client Secret Credentials"]["properties"]) == {
"client_id",
"client_secret",
"tenant_id",
}
assert (
azure_schemas["Azure Client Secret Credentials"]["additionalProperties"]
is False
)
assert azure_schemas["Azure Certificate Credentials"]["required"] == [
"client_id",
"certificate_content",
"tenant_id",
]
assert set(azure_schemas["Azure Certificate Credentials"]["properties"]) == {
"client_id",
"certificate_content",
"tenant_id",
}
assert (
azure_schemas["Azure Certificate Credentials"]["additionalProperties"]
is False
)
def test_oraclecloud_schema_includes_legacy_region_field(self):
schema = ProviderSecretField._spectacular_annotation["field"]
oraclecloud_schema = next(
@@ -78,7 +78,7 @@ from rest_framework_json_api import serializers
},
{
"type": "object",
"title": "Azure Static Credentials",
"title": "Azure Client Secret Credentials",
"properties": {
"client_id": {
"type": "string",
@@ -96,6 +96,28 @@ from rest_framework_json_api import serializers
},
},
"required": ["client_id", "client_secret", "tenant_id"],
"additionalProperties": False,
},
{
"type": "object",
"title": "Azure Certificate Credentials",
"properties": {
"client_id": {
"type": "string",
"description": "The Azure application (client) ID for authentication in Azure AD.",
},
"certificate_content": {
"type": "string",
"description": "Base64-encoded PEM certificate and private key content for certificate-based authentication.",
},
"tenant_id": {
"type": "string",
"description": "The Azure tenant ID, representing the directory where the application is "
"registered.",
},
},
"required": ["client_id", "certificate_content", "tenant_id"],
"additionalProperties": False,
},
{
"type": "object",
+1 -1
View File
@@ -107,7 +107,7 @@ Once you have decided the provider you want or need to add to Prowler, the next
- **SDK Providers**: Low complexity. You have mature examples like AWS, Azure, GCP, Kubernetes, etc. that you can leverage to implement your provider.
- **API Providers**: Medium complexity. You need to implement the authentication and session management, and the API calls to the provider. You now have NHN and MongoDB Atlas as example to follow.
- **Tool/Wrapper Providers**: High complexity. You need to implement the argument/output mapping to the provider and handle problems that the tool/wrapper may have. You now have IAC and the PowerShell wrapper as example to follow.
- **Hybrid Providers**: High complexity. You need to "customize" your provider, mixing the other types of providers in order to achieve the desired result. You have M365 (msgraph SDK + PowerShell wrapper) and GitHub (PyGithub SDK + graphql API requests) as examples.
- **Hybrid Providers**: High complexity. You need to "customize" your provider, mixing the other types of providers to achieve the desired result. You have M365 (msgraph SDK + PowerShell wrapper) and GitHub (PyGithub SDK + graphql API requests) as examples.
### Determining Regional vs Non-Regional Architecture
+1 -1
View File
@@ -525,7 +525,7 @@ with mock.patch(
):
```
As demonstrated in the code above, mocking both the AWS audit information and all utilized services is mandatory for proper test execution.
As demonstrated in the code above, mocking both the AWS audit information and all used services is mandatory for proper test execution.
#### Patching vs. Importing
+1 -1
View File
@@ -22,7 +22,7 @@ Google Cloud Security Command Center (Cloud SCC) is a centralized security and r
- **GCP-Centric:** While Cloud SCC is powerful within the GCP ecosystem, it is primarily focused on GCP and does not natively extend to multi-cloud environments without additional tools or connectors.
- **Cost Considerations:** As a managed service within GCP, costs can scale with the amount of data ingested and the complexity of the environment, especially as additional features or higher volumes of data are utilized.
- **Cost Considerations:** As a managed service within GCP, costs can scale with the amount of data ingested and the complexity of the environment, especially as additional features or higher volumes of data are used.
- **Dependency on GCP Services:** Cloud SCC's capabilities depend on other GCP services being enabled, such as Security Health Analytics and Web Security Scanner, which may increase overall complexity and cost.
@@ -45,7 +45,7 @@ To install Prowler as a Python package, use `Python >= 3.10, <= 3.13`. Prowler i
_Requirements_:
* Have `docker` installed: https://docs.docker.com/get-docker/.
* In the command below, change `-v` to your local directory path in order to access the reports.
* In the command below, change `-v` to your local directory path to access the reports.
* AWS, GCP, Azure and/or Kubernetes credentials
_Commands_:
@@ -6,7 +6,7 @@ In certain organizations, the severity of specific checks might differ from the
The custom metadata option offers a means to override default metadata set by Prowler.
You can utilize `--custom-checks-metadata-file` followed by the path to your custom checks metadata YAML file.
You can use `--custom-checks-metadata-file` followed by the path to your custom checks metadata YAML file.
## Available Fields
+1 -1
View File
@@ -99,7 +99,7 @@ def get_table(data):
## S3 Integration
If you are using Prowler Cloud with the S3 integration or that integration from Prowler CLI and you want to use your data from your S3 bucket, you can run the following command in order to load the dashboard with the new files:
If you are using Prowler Cloud with the S3 integration or that integration from Prowler CLI and you want to use your data from your S3 bucket, you can run the following command to load the dashboard with the new files:
```sh
aws s3 cp s3://<your-bucket>/output/csv ./output --recursive
@@ -64,7 +64,7 @@ This method grants permanent access and is the recommended setup for production
7. Click "Submit" to deploy the stack
![Click on submit](/images/providers/submit-third-page.png)
![Click Submit](/images/providers/submit-third-page.png)
</Tab>
<Tab title="Terraform">
To provision the scan role using Terraform:
@@ -2,7 +2,7 @@
title: 'Scanning Multiple AWS Accounts with Prowler'
---
Prowler enables security scanning across multiple AWS accounts by utilizing the [Assume Role feature](/user-guide/providers/aws/role-assumption) and [integration with AWS Organizations feature](/user-guide/providers/aws/organizations).
Prowler enables security scanning across multiple AWS accounts by using the [Assume Role feature](/user-guide/providers/aws/role-assumption) and [integration with AWS Organizations feature](/user-guide/providers/aws/organizations).
This approach allows execution from a single account with permissions to assume roles in the target accounts.
@@ -34,4 +34,4 @@ prowler scaleway
## Required Scaleway Permissions
The API key bearer needs read access to the IAM API in order to list users and API keys. The `IAMReadOnly` policy is sufficient. Refer to the [Scaleway IAM policy reference](https://www.scaleway.com/en/docs/identity-and-access-management/iam/reference-content/permission-sets/) for the full list of permissions.
The API key bearer needs read access to the IAM API to list users and API keys. The `IAMReadOnly` policy is sufficient. Refer to the [Scaleway IAM policy reference](https://www.scaleway.com/en/docs/identity-and-access-management/iam/reference-content/permission-sets/) for the full list of permissions.
@@ -69,7 +69,7 @@ To remove **another** user from your organization, use the [_Expel from organiza
#### Inviting Users
<Note>
Please be aware that at this time, an email address can only be associated with a single Prowler account.
Note that an email address can only be associated with a single Prowler account.
</Note>
Follow these steps to invite a user to your account: